Course Objectives
This training is designed to enable a SOC, CERT, CSIRT, or SOAR engineer to start working with Cortex XSOAR integrations, playbooks, incident-page layouts, and other system features to facilitate resource orchestration, process automation, case management, and analyst workflow.The course includes coverage of a complete playbook-development process for automating a typical analyst workflow to address phishing incidents. This end-to-end view of the development process provides a framework for more focused discussions of individual topics that are covered in the course.
Agenda
- 1 – Core functionality and Feature Sets
- 2 – Enabling and Configuring Integrations
- 3 – Playbook Development
- 4 – Classification and Mapping
- 5 – Layout Builder
- 6 – Solution Architecture – Docker
- 8 – Automation Development & Debugging
- 9 – Content Management
- 10 – Indicators
- 11 – Jobs and Job Scheduling
- 12 – Users and Role Management
- 13 – Integration Development
FREE
Interested in course?
Course Type: Instructor Led